Activity timeline
T1053.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 20 reports, and 60 of the 61 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1053.003 Cron is catalogued by MITRE ATT&CK under the Execution and Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of T1053 Scheduled Task/Job. Threadlinqs maps 61 of 2623 tracked threats (2.3%) to it; by severity that is 36 critical, 23 high, 2 medium.
Threats that use T1053.003 most often also use T1071.001 Web Protocols (47 threats), T1059.004 Unix Shell (46 threats), T1082 System Information Discovery (38 threats), T1190 Exploit Public-Facing Application (38 threats), T1005 Data from Local System (36 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
23 tracked threat actors appear in the threats that use T1053.003; the most frequent are JADEPUFFER (2), TeamPCP (2), WageMole (2), APT28 (1), APT32 (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1053.003.
Data sources
Telemetry that can reveal T1053.003, per MITRE ATT&CK.
- Command — Command Execution
- File — File Modification
- Process — Process Creation
- Scheduled Job — Scheduled Job Creation
Threat actors using it
Tracked threats
The 30 most recent of 61 tracked threats that use T1053.003.
- AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app…high
- Fortinet FortiMail critical path traversal flaw CVE-2026-104286 (FG-IR-26-175) exploited in zero-day attackscritical
- GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust…critical
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Thefthigh
- Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…critical
- Carbonato botnet: AI-agent-driven worm hijacks unauthenticated Docker daemons on port 2375 and installs the…high
- Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…critical
- Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian…high
- SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoorcritical
- StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Storescritical
- CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code Executioncritical
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2critical
- CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability (CVE-2025-62593) by…critical
- Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injectioncritical
- CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…critical
- Unpatched GeoServer Zero-Day SQL Injection (jsonArrayContains, GHSA-mqjf-5f49-2fjh) Under Active Exploitationcritical
- CVE-2026-65400: macOS Screen Sharing Authentication Bypass Grants Unauthenticated Root Accesscritical
- Three Critical VMware Flaws (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876) Allow Auth Bypass, RCE, and VM…critical
- Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Forcehigh
- SleeperGem: RubyGems Supply Chain Attack Uses Hijacked Dormant Maintainer Accounts to Weaponize…high
- SleeperGem Supply-Chain Campaign Uses Three Malicious RubyGems Packages to Backdoor Developer Machineshigh
- ClickFix, CrashFix, InstallFix, FileFix & GhostClaw: Growing Family of Copy-and-Paste Social Engineering…high
- SleeperGem: Compromised RubyGems Packages (git_credential_manager, Dendreo…high
- Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2…high
- NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for…high
- ClickLock Stealer: macOS ClickFix Infostealer Uses 210ms Process-Kill Loops and Fake Authentication Dialogs…high
- AsyncAPI npm Supply Chain Compromise: Import-Time Payload Delivery via Miasma Loadercritical
- AsyncAPI npm Supply Chain Attack: Pwn-Request GitHub Actions Compromise Deploys Miasma Tasking Frameworkcritical
- Check Point AI Security Report 2026: AI Shifts from Attack Tool to Autonomous Intrusion Operator (VoidLink…high
Detection coverage
Threadlinqs maintains 175 detection rules mapped to T1053.003 (SPL 56, KQL 52, Sigma 67). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1053 Scheduled Task/Job — 271 tracked threats at the technique level.